Hush Line Fixes Security Issue in Whistleblower Management System
CVE-2024-55888

7.1HIGH

Key Information:

Vendor
Scidsg
Status
Hushline
Vendor
CVE Published:
12 December 2024

Summary

Hush Line, an open-source whistleblower management system, has a vulnerability due to a misconfigured production server that fails to implement a content security policy or necessary security headers. This flaw, present in versions 0.1.0 to 0.3.4, potentially enables attackers to bypass cross-site scripting (XSS) filters, which could compromise the security of user data and the application. The vulnerability has been addressed in version 0.3.5, which includes critical security updates.

Affected Version(s)

hushline >= 0.1.0, < 0.3.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.